Email Security and Social Engineering Analyst
Summary
We are seeking an associate to join the Security Operations team as an Email Security Analyst. This role will help protect the organization, our associates, and our customers by managing email security controls and investigating suspicious messages. The analyst will work extensively in Proofpoint and Outlook, triage reported phishing emails, support incident response, and help improve how we detect and respond to email-based threats. The ideal candidate brings a healthy sense of paranoia: someone who notices when details do not add up, verifies assumptions, follows evidence, and remains appropriately skeptical without losing sight of business context. Just as important, this associate must communicate clearly and calmly with technical teams, business partners, leaders, and end users.
Why Consider This Opportunity?
This position is a great opportunity to be on the front line of threats impacting our associates and customers. You will see firsthand—and help defend against—cybersecurity and social engineering threats while gaining hands-on experience with enterprise email security, phishing response, digital risk protection, threat analysis, incident response, and security operations. You will also partner with teams across the company to investigate issues, contain threats, and protect the organization.
Essential Duties And Responsibilities
- Use the Proofpoint Secure Email Gateway and related Proofpoint tools to review and manage email traffic, alerts, quarantines, and threat activity.
- Lead day-to-day phishing response by monitoring, triaging, investigating, containing, and documenting suspicious emails reported by associates and customers.
- Address ServiceNow tickets related to phishing, email security, email delivery, and other assigned security issues within established service-level expectations.
- Troubleshoot email delivery issues by reviewing message tracking, filtering decisions, quarantines, authentication results, policy routes, allow and block controls, and other relevant data.
- Analyze message headers, sender behavior, URLs, attachments, redirects, and message context to determine whether an email is legitimate, suspicious, or malicious.
- Investigate social engineering activity, including phishing, impersonation, business email compromise, credential theft, malicious links, and fraudulent requests.
- Support digital risk protection activities by identifying, reviewing, and escalating external threats such as brand impersonation, fraudulent domains, malicious websites, and other risks targeting the organization, its associates, or its customers.
- Perform Tier 1 phishing triage and escalate confirmed threats or complex investigations as appropriate.
- Use sandboxing, threat intelligence, endpoint, identity, and logging tools to validate findings and determine potential impact.
- Support email authentication and protection controls, including DMARC, SPF, DKIM, policy routes, and email firewall rules.
- Search for related messages, contain threats, remove malicious emails, and support affected-user response actions.
- Support incident response for compromised user accounts and devices, including evidence collection, scoping, containment, escalation, remediation coordination, and documentation.
- Work with Identity, Endpoint, Security Operations, and other response teams to protect affected users, reset or secure access, isolate devices when appropriate, and confirm that threats have been contained.
- Document investigations, evidence, decisions, and actions accurately and consistently.
- Communicate findings and recommended actions to associates in clear, professional, and timely language.
- Partner with Security Operations, Threat Management, Security Engineering, Messaging, Identity, and other teams during investigations and incidents.
- Identify recurring patterns, control gaps, and opportunities to improve phishing detection, email delivery support, digital risk protection, and incident response processes.
- Participate in an after-hours rotation or respond outside normal business hours when required.
- Perform other duties as assigned.
What Success Looks Like
- You are naturally curious and willing to investigate beyond the first obvious answer.
- You maintain a healthy sense of paranoia while making evidence-based, practical decisions.
- You can distinguish unusual activity from normal business behavior and know when to ask more questions.
- You communicate with empathy and confidence, especially when an associate may be worried about a suspicious message or possible compromise.
- You remain organized and accurate while managing a queue of time-sensitive work.
- You explain technical findings in plain language and tailor your message to the audience.
- You take ownership, follow through, and escalate promptly when risk or impact is unclear.
Qualifications
- Current associate in good standing with demonstrated reliability, sound judgment, and attention to detail.
- Strong written and verbal communication skills, including the ability to interact effectively with associates, leaders, technical teams, and external contacts.
- Ability to analyze incomplete or conflicting information, recognize patterns, and make well-reasoned decisions.
- Ability to follow procedures while adapting to new attack techniques and changing business conditions.
- Comfort handling sensitive information and maintaining confidentiality.
- Ability to manage competing priorities and work independently in a fast-paced environment.
- General proficiency with Microsoft Office and collaboration tools.
- Education and experience sufficient to perform the responsibilities of the role; relevant internal experience and transferable skills will be considered.
Preferred Experience
- Experience in Information Security, fraud, investigations, technology support, risk management, compliance, customer service, operations, or another role requiring careful review and sound judgment.
- Familiarity with phishing, business email compromise, social engineering, malware, or common email threats.
- Experience with Proofpoint, Microsoft 365 email security, Splunk, endpoint detection and response tools, ticketing systems, and/or security sandboxes.
- Understanding of email headers, URLs, domains, DNS, DMARC, SPF, or DKIM.
- Experience documenting investigations or communicating findings to non-technical audiences.
- Relevant security training or certifications, including Security+, CySA+, or Proofpoint certifications.